| @@ -416,8 +416,14 @@ | ||
| 416 | 416 | * @return array Response data |
| 417 | 417 | * @throws \Exception If request fails |
| 418 | 418 | */ |
| 419 | 419 | private function make_request(string $endpoint, array $data): array { |
| 420 | + // The user's daily ceiling and kill switch are enforced here, at the | |
| 421 | + // one place every outbound Gemini call passes through, so no feature | |
| 422 | + // path can bypass them by forgetting to ask first (#448). | |
| 423 | + Spend_Guard::guard(); | |
| 424 | + Spend_Guard::record(); | |
| 425 | + | |
| 420 | 426 | // Send the API key in the x-goog-api-key header rather than the URL |
| 421 | 427 | // query string, which is logged by servers, proxies and referrers. |
| 422 | 428 | $url = "https://generativelanguage.googleapis.com/v1beta/models/{$this->model}:{$endpoint}"; |
| 423 | 429 | |